IBM Datastage On Cloud Pak Data
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in IBM Datastage On Cloud Pak Data.
By the Year
In 2026 there have been 23 vulnerabilities in IBM Datastage On Cloud Pak Data with an average score of 8.2 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 23 | 8.19 |
It may take a day or so for new Datastage On Cloud Pak Data vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent IBM Datastage On Cloud Pak Data Security Vulnerabilities
IBM DataStage on Cloud Pak for Data 5.4.0.0 Auth Bypass Causing DOS
CVE-2026-80378
8.5 - High
- September 10, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper authorization.
AuthZ
IBM DataStage on Cloud Pak for Data 5.4.0.0: CSRF Enables Unauthorized Actions
CVE-2026-80380
7.1 - High
- September 10, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery.
Session Riding
IBM DataStage Cloud Pak 5.4.0.0 IDOR Causing Runtime Cache Manipulation & DoS
CVE-2026-80434
7.4 - High
- September 10, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and cause a denial of service due to an insecure direct object reference.
Insecure Direct Object Reference / IDOR
IBM DataStage CloudPak Path Traversal 5.4.0.0 Enables Auth Remote File Write
CVE-2026-80424
9.1 - Critical
- September 10, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction.
Directory traversal
IBM DataStage Cloud Pak 5.4: Authenticated DOS via RabbitMQ Deletion
CVE-2026-80436
8.5 - High
- September 10, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization.
AuthZ
IBM DataStage CP4D 5.4.0.0 ds-canvas: Auth. tenant controls outbound fetch URLs
CVE-2026-81207
8.5 - High
- September 10, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant with no project membership or role fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller. The ds-canvas pod sits on the OpenShift overlay with reach to co-tenant services, in-cluster CP4D APIs, and link-local addresses. Scope is Changed, confidentiality High (response-reflecting), integrity Low (GET-only side-effects).
SSRF
IBM DataStage Cloud Pak 5.4 IDOR & Path Traversal via Log Files
CVE-2026-81210
7.7 - High
- September 10, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String.format path on the shared /ds-storage RWX PVC and returns the file with no project ACL pure IDOR plus traversal. Read is constrained to files named job.log/error.log, but DataStage job logs routinely carry connection strings, {dsnextenc} ciphertexts (decryptable via d2-f023), and customer-data row samples. This is the operator's tenant-to-tenant PVC-leakage threat verbatim; MEDIUMHIGH via threat match.
Insecure Direct Object Reference / IDOR
IBM DataStage 5.4.0.0 Path Traversal Enables Auth Tenant Ruleset Overwrite
CVE-2026-81540
8.5 - High
- September 10, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability.
Directory traversal
IBM DataStage 5.4.0.0 RCE via improper OS command escaping
CVE-2026-81550
8.8 - High
- September 10, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Shell injection
IBM DataStage Cloud Pak 5.4.0 Path Traversal Enables Remote File Write
CVE-2026-81551
8.8 - High
- September 10, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability.
Directory traversal
IBM DataStage on Cloud Pak for Data 5.4.0.0 Path Traversal Remote Auth Attack
CVE-2026-81554
8.8 - High
- September 10, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.
Directory traversal
IBM DataStage 5.4.0.0 APT: Absolute-Path Traversal Remote Auth Get Sensitive Info
CVE-2026-82092
8.8 - High
- September 10, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.
Absolute Path Traversal
IBM DataStage Cloud Pak 5.4.0.0 OS Command Injection via Improper Escaping
CVE-2026-82095
8.8 - High
- September 10, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Shell injection
IBM DataStage on Cloud Pak for Data 5.4.0.0 SSRF RCE
CVE-2026-82097
8.8 - High
- September 10, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.
SSRF
Remote Authenticated Command Injection in IBM DataStage Cloud Pak 5.4.0.0
CVE-2026-82098
8.8 - High
- September 10, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Shell injection
IBM DataStage on Cloud Pak 5.4.0.0: Authenticated RCE via OS Command Injection
CVE-2026-82099
8.8 - High
- September 10, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Shell injection
IBM DataStage 5.4.0.0 Path Traversal DoS (Auth)
CVE-2026-82100
9.6 - Critical
- September 10, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.
Directory traversal
IBM DS Cloud Pak 5.4 Improper Auth Bypass Remote Data Exfil
CVE-2026-82107
9.6 - Critical
- September 10, 2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.
authentification
IBM DataStage 5.1.2-5.3.0 Auth Cmd Exec via Job Subroutine
CVE-2025-13686
6.3 - Medium
- March 03, 2026
IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input through the job subroutine component.
Shell injection
IBM DataStage on Cloud Pak for Data 5.1.2-5.3.0 UDF RCE via input validation
CVE-2025-13687
6.3 - Medium
- March 03, 2026
IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input through the user-defined function component.
Shell injection
IBM DataStage CloudPak 5.1.2-5.3.0 Cmd Injection via Wrapped Cmd Comp
CVE-2025-13688
6.3 - Medium
- March 03, 2026
IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input through the wrapped command component.
Shell injection
IBM DataStage on Cloud Pak for Data 5.1.2-5.3.0 - HTTP Resp Sensitive Disclosure
CVE-2025-13616
6.5 - Medium
- March 03, 2026
IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be used in further attacks against the system.
Exposure of Sensitive System Information to an Unauthorized Control Sphere
IBM DataStage Cloud Pak 5.1.25.3.0 Sensitive Data in HTTP Response
CVE-2025-13691
8.1 - High
- February 17, 2026
IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be used to impersonate other users in the system.
Exposure of Sensitive System Information to an Unauthorized Control Sphere
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for IBM Datastage On Cloud Pak Data or by IBM? Click the Watch button to subscribe.